2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55488 | MEDIUM | 6.5 | 0.3% | Jan 22, 2025 | A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip... |
| CVE-2024-42013 | MEDIUM | 6.4 | 0.2% | Jan 22, 2025 | In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac... |
| CVE-2024-42012 | MEDIUM | 5.7 | 0.1% | Jan 22, 2025 | GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c... |
| CVE-2024-10929 | MEDIUM | 5.1 | 0.2% | Jan 22, 2025 | In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may ... |
| CVE-2024-24432 | MEDIUM | 5.3 | 0.3% | Jan 22, 2025 | A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service... |
| CVE-2024-13447 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2024-13360 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2024-13319 | MEDIUM | 6.1 | 0.3% | Jan 22, 2025 | The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-13406 | MEDIUM | 6.1 | 0.3% | Jan 22, 2025 | The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id... |
| CVE-2024-12117 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-12879 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-13590 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short... |
| CVE-2024-13584 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13426 | MEDIUM | 5.3 | 0.5% | Jan 22, 2025 | The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2... |
| CVE-2024-49736 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo... |
| CVE-2024-49733 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ... |
| CVE-2024-43763 | MEDIUM | 6.5 | 0.1% | Jan 21, 2025 | In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul... |
| CVE-2024-24443 | MEDIUM | 6.5 | 0.3% | Jan 21, 2025 | An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface ... |
| CVE-2024-45478 | MEDIUM | 4.8 | 0.5% | Jan 21, 2025 | Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended ... |
| CVE-2024-24445 | MEDIUM | 6.5 | 0.3% | Jan 21, 2025 | OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protoc... |
| CVE-2024-57545 | MEDIUM | 5.5 | 0.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_nu... |
| CVE-2024-57544 | MEDIUM | 5.5 | 0.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is... |
| CVE-2024-57543 | MEDIUM | 5.5 | 0.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) ... |
| CVE-2024-57541 | MEDIUM | 5.5 | 0.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_s... |
| CVE-2024-57540 | MEDIUM | 6.5 | 0.7% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is cop... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now